<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to solve the error message: an error ocured while fetching data in a splunk dashboard using post-process search? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-solve-the-error-message-an-error-ocured-while-fetching/m-p/313714#M20106</link>
    <description>&lt;P&gt;You need to make sure that the &lt;CODE&gt;TTL&lt;/CODE&gt; ("Time To Live") of your scheduled search is at &lt;EM&gt;least&lt;/EM&gt; as long as the periodicity of the search.  If your search runs every day than the search's TTL should be at least 60*60*24 or greater.  If not, you will get this error.  You can check &lt;CODE&gt;TTL&lt;/CODE&gt; like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|rest/servicesNS/-/-/saved/searches
| fields dispatch.ttl title eai:acl.app description search disabled triggered_alert_count actions action.script.filename alert.severity cron_schedule
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;A href="https://www.splunk.com/blog/2012/09/12/how-long-does-my-search-live-default-search-ttl/" target="_blank"&gt;https://www.splunk.com/blog/2012/09/12/how-long-does-my-search-live-default-search-ttl/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 14:16:17 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2020-09-29T14:16:17Z</dc:date>
    <item>
      <title>how to solve the error message: an error ocured while fetching data in a splunk dashboard using post-process search?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-solve-the-error-message-an-error-ocured-while-fetching/m-p/313713#M20105</link>
      <description>&lt;P&gt;Every time I run the dashboard this message appears and then splunk server goes down. Dashboard is based in a post-process search where the base searches are as scheduled reports. Why does this happens?&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2017 18:14:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-solve-the-error-message-an-error-ocured-while-fetching/m-p/313713#M20105</guid>
      <dc:creator>sonila</dc:creator>
      <dc:date>2017-05-29T18:14:26Z</dc:date>
    </item>
    <item>
      <title>Re: how to solve the error message: an error ocured while fetching data in a splunk dashboard using post-process search?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-solve-the-error-message-an-error-ocured-while-fetching/m-p/313714#M20106</link>
      <description>&lt;P&gt;You need to make sure that the &lt;CODE&gt;TTL&lt;/CODE&gt; ("Time To Live") of your scheduled search is at &lt;EM&gt;least&lt;/EM&gt; as long as the periodicity of the search.  If your search runs every day than the search's TTL should be at least 60*60*24 or greater.  If not, you will get this error.  You can check &lt;CODE&gt;TTL&lt;/CODE&gt; like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;|rest/servicesNS/-/-/saved/searches
| fields dispatch.ttl title eai:acl.app description search disabled triggered_alert_count actions action.script.filename alert.severity cron_schedule
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;A href="https://www.splunk.com/blog/2012/09/12/how-long-does-my-search-live-default-search-ttl/" target="_blank"&gt;https://www.splunk.com/blog/2012/09/12/how-long-does-my-search-live-default-search-ttl/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:16:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/how-to-solve-the-error-message-an-error-ocured-while-fetching/m-p/313714#M20106</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2020-09-29T14:16:17Z</dc:date>
    </item>
  </channel>
</rss>

